Traditional hardware wallets store the full private key in a single secure element. MPC eliminates the concept of a single key — and with it, the single point of compromise.
Multi-Party Computation for digital asset custody addresses the fundamental weakness of traditional wallet security: a single private key that, if compromised, results in total loss of the funds it controls. In an MPC wallet, the private key never exists as a complete entity on any single device. Instead, key material is distributed across multiple parties using cryptographic protocols (ECDSA threshold signatures) that allow signing without any party ever reconstructing the full key. An attacker who compromises one party has nothing — they need to compromise the signing threshold simultaneously. For institutions managing digital assets worth millions, this is the difference between a security breach and a catastrophic loss event. PROPELOO builds MPC wallet infrastructure for exchanges requiring institutional-grade custody, asset managers building digital asset products, and enterprises with treasury management requirements that demand defence-in-depth key security.
Frequently Asked Questions
How is MPC different from multi-sig?
Multi-sig (e.g., Gnosis Safe 3-of-5) requires multiple parties to each sign independently using their full keys, and the blockchain enforces the quorum requirement. MPC uses a cryptographic protocol where parties cooperate to produce a single standard signature — no key ever exists in full, and the blockchain sees a normal single-signature transaction. MPC has better privacy (the threshold scheme is invisible on-chain) and works on all chains without smart contract support.
What is key refresh and why is it important?
Key refresh re-randomises the key shares without changing the public key or moving the funds. After a refresh, the old shares become cryptographically worthless — an attacker who stole an old share cannot use it after refresh. This defeats long-term compromise scenarios where an attacker waits to collect enough shares over time. We recommend key refresh every 30-90 days.
Can you help us migrate from Fireblocks to a custom MPC system?
Yes. Migration requires generating new key material (the Fireblocks keys cannot be extracted — that is by design), moving funds to the new wallets, and setting up the operational workflows. We run both systems in parallel during migration, starting with lower-value wallets before migrating the main treasury. The migration timeline is typically 8-12 weeks.
How many parties should we have in our MPC scheme?
Depends on your use case. Hot wallets: 2-of-3 (two company devices + one hardware backup) balances security and operational speed. Cold storage: 3-of-5 with geographic distribution (e.g., three offices, two secure facilities). For enterprises: match your existing financial controls — if your treasury policy requires dual authorisation, a 2-of-3 scheme maps to that model.
Which MPC threshold schemes do you implement?
We implement state-of-the-art threshold signature protocols including CMP (Canetti, Gennaro, Goldfeder, Makriyannis, Peled 2020) and FROST (Flexible Round-Optimized Schnorr Threshold) for Ed25519 and Secp256k1 curves. These provide active security against malicious adversaries, non-interactive key generation options, and minimal network round-trips.
How do you enable gasless transactions and account abstraction with MPC?
We combine MPC key generation with ERC-4337 smart accounts. The MPC key share acts as the signer for UserOperations, while an ERC-4337 Paymaster contract sponsors gas fees or accepts token payment (e.g., USDC). This gives users a seamless Web2-like experience without requiring native ETH or SOL for transaction fees.
What disaster recovery and social recovery options exist for end users?
We architect redundant key share backup hierarchies: one share stored locally in secure hardware storage (Keychain/Secure Enclave), one encrypted in cloud backup (iCloud/Google Drive), and one managed by a quorum of institutional recovery guardians or social contacts. Users can recover their wallet without seed phrases if their device is lost.
Can institutions enforce multi-tier approval policies before MPC signing executes?
Yes. We integrate policy engine layers that evaluate transaction rules prior to initiating the MPC signing protocol. Rules can enforce multi-level management approvals, whitelisted destination addresses, time-window transaction caps, and biometric authentication before key shares participate in signature computation.